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1 Introduction 


A normative system is defined as any set of interacting agents whose behav- 
ior can usefully be regarded as norm-directed [9]. Most organizations, and more 
specifically institutions, fall under this definition. Interactions in these normative 
systems are regulated by normative templates that describe desired behavior in 
terms of deontic concepts (obligations, prohibitions and permissions), deadlines, 
violations and sanctions. Agreements between agents, and between an agent and 
the society, can then be specified by means of contracts. Contracts provide flex- 
ible but verifiable means to integrate society requirements and agent autonomy, 
and are an adequate means for the explicit specification of interactions [14]. 
From the society perspective, it is important that these contracts adhere to the 
specifications described in the model of the organization. If we want to automate 
such verifications, we have to formalize the languages used for contracts and for 
the specification of organizations. 

In [13] we presented the logic LCR, which is based on deontic temporal logic. 
LCR is an expressive language for describing interaction in multi- agent systems, 
including obligations with deadlines. Deadlines are important norms in most 
interactions between agents. Intuitively, a deadline states that an agent should 
perform an action before a certain point in time. The obligation to perform the 
action starts at the moment the deadline becomes active. E.g. when a contract 
is signed or approved. If the action is not performed in time a violation of the 
deadline occurs. It can be specified independently what measure has to be taken 
in this case. 

In previous work, we have advocated the use of declarative deadline specifi- 
cations, as it facilitates the check for compliance to a deadline and enables rea- 
soning about norms before the planning process determines the next sequence 
of actions [5]. In this paper we investigate the deadline concept in more detail. 

The paper is organized as follows. Section 2 defines the variant of CTL we 
use. In section 3, we discuss the basic intuitions of deadlines. Section 4 presents a 
first intuitive formalization for deadlines. In section 5, we look at a more complex 
model for deadlines trying to catch some more practical aspects. Finally, in 
section 6 we present issues for future work and our conclusions. 
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Preliminaries: CTL 


The reader can find the definitions for the branching time logic CTL in the 
literature (e.g. [3, 7, 4]). But, since we need a specific variant of the until operator, 
we define CTL here explicitly. 

Well-formed formulas of the temporal language CcTL are defined by: 

tp,ip y ... := p | -up | </? Ai/> | Ea \ Aa 
a,/?, . • ■ := (pU e i> | X<p 

where py^p represent arbitrary well-formed formulas, and where the p are 
elements from an infinite set of propositional symbols V. Formulas a,/?, . . . are 
called ‘path formulas 5 . We use the superscript ‘e 5 for the until operator to denote 
that this is the version of ‘the until 5 where p is not required to hold for the point 
where ip, i.e., the point where cp is excluded. However, the present state is not 
excluded, which means that our until operator is reflexive. This gives us the 
following- informal meanings of the until operator: 

E(pU e ip) : there is a future for which eventually, at some point m, the condi- 
tion ip holds, while p holds from now until the moment before m 

We define all other CTL-operators as abbreviations. Although we do not use 
all of the LTL operators X, F , and G in this paper, we give their abbreviations 
(in combination with the path quantifiers E and A) in terms of the defined op- 
erators for the sake of completeness. We also assume the standard propositional 
abbreviations. 

EFp = de f E(TU e p) AGp ~def -'EF-^tp 

AFp = de f A(TU e p) EG<p ~def ~^AF^p 

A(<pUi>) = def A(pU e (p A ip)) E(<pV1>) = def E(pU e (p A ip)) 

The informal meanings of the formulas with a universal path quantifier are as 
follows (the informal meanings for the versions with an existential path quantifier 
follow trivially): 


A(pUip) : for all futures, eventually, at some point the condition ip will hold, 
while <p holds from now until then 
AXip : at any next moment tp will hold 
AFp : for all futures, eventually tp will hold 
AGtp : for all possible futures p holds globally 

A CTL model M = (5, 7£,7t), consists of a non-empty set S of states, an 
accessibility relation 1Z , and an interpretation function ir for propositional atoms, 
A full path a in M is a sequence a — So,Si,S2,. ■ • suc -d f° r ever Y * ^ 

Si is an element of S and SiJZsi+i , and if a is finite with $ n its final situation, 
then there is no situation s n + i in S such that s n 7£s n +i- We say that the full 
path a starts at s if and only if s 0 = s. We denote the state Si of a full path 



a = so, si, S 2 , . . . in M by cr* . Validity M, s [= <p, of a CTL-formnIa <p in a world 
s of a model M — (S,H,7r) is defined as: 


M t s \= p &sG7r(p) 

M y s \= —*p o not My s [= <p 

M, s }= <p A ip & My $\= <p and M, s (= -0 

My s |= Ea 3cr in M such that cro — s and M, cr, s £= a 

M, s j= Aa ^ Vcr in M such that cr 0 — s it holds that M, a, s f= a 

My(JyS\= X(f & My (Tl ^=(f> 

My <jy s (= & 3n > 0 such that 

( 1 ) My(r n j= tp and 

(2) Vi with 0 < i < n it holds that My <?i f= tp 


Validity on a CTL model M is defined as validity in all states of the model. If 
<p is valid on a,CTL model M, we say that M is a model for <p. General validity 
of a formula <p is defined as validity on all CTL models. The logic CTL is the 
set of all general validities of £cTL over c ^ ass °f CTL models. 


3 Basic choices for the formalization of deadlines 

In this section we study some choices to make when developing a formal model for 
deadlines. The deontic aspect of deadlines is formalized by introducing a set A of 
agent identifiers and a propositional constant Viol(a ) for each a € A in ^CTL- 
The general idea is that the violation condition holds (i.e., the propositional 
constant Viol( a) is true) at those moments where agent a violates a deontic 
deadline. This enables us to reason about violations explicitly, and about what 
to do if they occur, which is a distinctive feature of deontic reasoning. We model 
deadline conditions as propositions. This seems a reasonable choice given that 
we do not want to model a deadline in a logic of explicit time (real time). Our 
view is more abstract, and a deadline is simply a condition true at some point 
in time. We use the symbols 5 and 7 to denote deadline propositions. 

Although the basic idea of a deadline is very simple it appears that the 
details are intricate. We suggest that one of the reasons is that in order to 
model deadlines, we need to model a causal relation between non-fulfilment of an 
obligation and, so called, ‘violation conditions’. Causal relations are notoriously 
hard to formalize. Figure 1 pictures the situation. 

The figure shows several possible futures from a point where a deadline is in 
force. In some futures the required action does not take place and a violation 
results after the deadline is reached. For other futures, the action does take place 
before the deadline is reached, and no violations appear after the action. 

We denote a deadline for agent a saying that it is obliged to achieve the 
condition p before 6 holds, by the formula O a (p < d). We will give a formal 
definition of the semantics of this formula after, in the next sections, we have 
discussed some basic choices to make. 
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Fig. 1. The semantics of deadlines 


3.1 Do obligations persist after the deadline? 

A first distinction we make is between deadline obligations that are discharged 
by a failure to meet the deadline, and deadline obligations where the obligation 
is not discharged at the deadline. For a deadline of the first type it makes no 
sense to perform the action after the deadline passes. E.g., submitting a paper 
after the deadline of a conference has no effect. An example of the second type 
is the situation where one has to pay a fine for some traffic offense by the end 
of the month. Also when one does not pay, the obligation to pay persists (see 
also the work of Brown on Standing obligations’ [2]). Yet another category are 
the ‘repetitive obligations’, where the same deadline obligation is repeated over 
a period of time. For example monthly mortgage payments. 


3.2 What if the deadline is never or immediately met? 

We first consider the case where 6 equals J_. Clearly, _L is a condition that will 
be "never met. A natural question is, whether it is actually possible to have a 
deadline obligation for a deadline that never occurs. One could choose to say that 
this is impossible, which leads to the optional property (1) t= ^ O a {p < -L). This 
is the case for our deadline definition is section 5, because, in the definition given 
there, we assume that a deadline obligation can only be in force if the deadline 
condition actually occurs at some point in the future. Another possibility is to 
say that for any condition p such an obligation is actually always valid, but void, 
i.e, without any ‘force’. This corresponds to the property (2) O a (p < J_). Such 
obligations can be considered void, because they cannot be violated; since the 
deadline never occurs, there will never be a point in time where non-compliance is 
evaluated. It might be argued that a similar situation occurs in standard deontic 
logic [15], where we have f= OT, which corresponds with the void obligation for 
a tautology (also something that can never be violated). Our formalization in 
section 4 satisfies this property. 

Obviously, the third possibility is that neither property (1), nor property (2) 
is satisfied. For instance, one could argue that an obligation for a deadline that 
never occurs, i.e., O a (p < _L), is not void, but should be interpreted as follows: 
the impossibility of the deadline condition means that the deadline is ill-defined, 



but this does not imply that the agent is free to postpone his duty forever: he 
has to comply at some future point anyway (where that point can be arbitrarily 
far in the future). The corresponding formula is: (3) |= O a (p < ±) — ► AFp. 

Now consider the case where 5 equals T. This means that the deadline con- 
dition is met trivially, in the current state. One possible view is that in this case, 
we can still comply to the obligation by ensuring that also p is met in the current 
state. The corresponding property is: (4) j= O a (p < T) — ► Viol(a) V p. 

Alternatively, we might argue that it is impossible to comply to a deadline 
for which the deadline condition is true now . For an agent, it takes some time 
to decide whether or not to comply, and to bring about the condition p the 
obligation is concerned with. Then, if the deadline condition is true now, there is 
no time left for this process, and the agent will inevitably violate the obligation. 
In our definitions of section 4 and 5, we take this aspect into account. The 
corresponding property is (5) j= O a {p < T) — ► FioZ(a), which is satisfied by 
the deontic deadline definition in sections 4 and 5. Note that under this view, 
the violation is not avoided if accidentally the condition p is true in the present 
state. This is because under this view, conditions are linked to agents that bring 
them about, which is a decision they make in the previous state, as we explain 
later on. 

Finally one short comment about the thought that we have to account for 
the situation that a deadline condition might have been true in the past. Clearly 
we do not have to consider this situation, because it is impossible to have an 
obligation to do something before something that occurred in the past. 

3.3 What if the accomplishment is accidentally, never or trivially 
achieved? 

First we address the question whether it counts as compliance to a deadline 
obligation when the condition that is obliged occurs ‘accidentally’. It is possible 
that the state p occurs without any effort or intention of the agent for whom 
the obligation holds. E.g. if a person is obliged to write the introduction of a 
paper, fails to do so, but a co-author writes the introduction (because he is 
tired of waiting for that person). Did the person fulfill his obligation or not? If 
obligations are personal, should it not be the case that also the achievements p 
are personal? After all, we do not want that if another agent, or ‘nature’, brings 
about the achievement, the agent with the obligation has complied. We encounter 
a basic choice to make here. If we do not want our obligations to be personal, we 
do not have to personalize the achievements. But, if we do want our obligations 
to be personal, we somehow have to link achievements to agents. There is a vast 
amount of literature about personalizing the achievement of conditions [10, 1, 
8,6]. Usually, such theories are called ‘logics of action and/or agency’. Inspired 
by the work of Porn [10], we use the stit operator E a p, to denote that agent a 
achieves condition p. A difference with the stit operator of Pom is that in our 
temporal setting, performing a ‘seeing to it’ action takes one time-step. That 
is, our stit-operator obeys E a p — * Xp, and not (= E a p — ► p, which holds for 

most other agency operators. 



Our next question concerns the case where the achievement can never be 
reached. For instance, one might think of a personal obligation for a condition not 
under control of an agent. An example is the condition J_. Again, a first option 
is to say that obligations of the form 0 a (_L < <5) are impossible or inconsistent. 
After all, it seems reasonable to take the position that one can never be obliged 
to achieve the impossible. This leads to the optional property (6) (= “ i O a (_L < 
£), which is similar to standard deontic logic’s D-axiom -»0_L [15]. However, 
we might also take the position that one can have an obligation to achieve 
the impossible. But, since 0 a (-L < <5) expresses that we have to achieve the 
impossible before the deadline condition 6 occurs, we have to conclude that this 
leads to the view that there will certainly be a violation whenever 5 occurs 
for the first time. This leads to the optional property: (7) [= O a (J_ < <5) — > 
->E(-^6U e (6 A ^Viol(a))). 

Finally we consider the case where the accomplishment is T. How to deal with 
this situation depends on whether we consider the obligation to be personal or 
not. As discussed, for' the personal case, we have to use an agency operator. 
In most logics of agency, T cannot be achieved by any agent (|= ->E a T). This 
motivates the optional property (8) (= ->0 a (T < 5 ). However, if obligations are 
not personal, this is not necessarily intuitive. At this point we might not want 
to digress from standard deontic logic, where the obligation for a tautology is 
always valid. Thus we have the optional property (9) \= 0 a (T < J). 


4 A simple formalization 

After having discussed some choices for modelling deadlines in the previous 
section we will present a first logical formalization. 

As mentioned, E a p indicates that the agent a sees to it that p becomes true. If 
E a p is true at some point in time, then p is true at the next point in time. We use 
the symbols p and a for propositions that embody some kind of accomplishment 
being established before a deadline condition occurs. 

Let M be a CTL model, s a state, and a — oo, cr 1} 02 , . . . a full path in M. 
A straightforward modal semantics for the operator O a (p < S) is then defined 
as follows: 

M ) s |= O a (p < J) o Vcr with ao — s, Vj : 
if M , <Tj |= S 

and Vi with 0 < i < j : M, di \= ~^E a p, 
then M, crj |=VioZ(a) 

This says: if at some future point the deadline occurs, and until then the 
result has not yet been achieved, then we have a violation at that point. This 
semantic definition is equivalent to the following definition as a reduction to 
CTL: 


Oa(p < S) Sde/ ~^E{^E a p U e (S A ^Viol(a))) 



This formula just expresses the negation of the situation that should be 
excluded when a deontic deadline is in force. In natural language this negative 
situation is: ‘<5 becomes true at a certain point, the achievement has not been 
met until then, and there is no violation at 5\ This shows that it is fairly easy 
to show the equivalence of the semantic definition and the definition in terms of 
CTL (details left to the reader). The above defined deadline operator persists 
after reaching the deadline, and satisfies properties 2, 5, and 7 discussed in the 
previous section. 

However, despite the nice properties and the simple and elegant represen- 
tation of the concepts, the definition does not cover the intuitions of figure 1 
completely. This becomes apparent when we look at a situation in which an 
agent a achieves p before a certain condition 5 becomes true. Whenever this 
appears to be true it follows that a has the obligation to achieve p. I.e., the fact 
that an agent will achieve something implies that he is obliged to achieve it. 

We suggest that the source of this problem might be that we have failed to 
formalize the ‘causal link’ that intuitively relates failures to comply to the obli- 
gation and occurrences of the violation condition. In the truth condition above, 
we have only dealt with one direction of the implicative relation between non- 
compliance and violation: we have captured that when there is non-compliance, 
there is also a violation. But we have failed to capture a reverse implicative 
direction saying that only if there is non-compliance there can be violations. 

In the next section we will propose an extended definition that tries to es- 
tablish this causal link between non-achievements and violations. 

5 The causal approach 

In [13] we have already attempted to capture some aspects of the causal link 
between non-achievement and violations. However that formalization did not 
force the condition that there can never be a violation of the obligation before 
the deadline condition holds. It also allows situations where p is achieved while 
there is still a violation after the deadline condition. Somehow we have to ‘close’ 
the possible worlds in a way that either we have the achievement and no violation 
after that or a violation and no achievement, before the deadline. In this way we 
approach most closely that the achievement of p causes the -» Viol (a ). 

The definition given below differs from the one in section 4 on three important 
points. First of all, for a deadline obligation to be valid, it now requires that the 
deadline condition actually occurs at some point in the future. A second crucial 
difference is that we strengthen the ‘if’ construction in the truth condition to 
an fif-and-only-if 5 condition, by which we attempt to capture the causal relation 
between non-compliance and violation. This £ if-and-only-if’ condition takes the 
form of a disjunction (the ‘or’ in the truth condition below) saying that either 
E a p holds (in time), meaning that there is compliance, or E a p does not hold 
before <5, in which case there is non-compliance. Note that the disjunction is 
exclusive, because either p is achieved or not, but not both. Finally, we require 
violations to persist ones they have occurred, and we require non- violations 



to persist when the achievement is accomplished In time, or if no deadline or 
achievement condition has yet occurred. 


M,5t= O a (p < <5) iff Vcr with oo = s : 3j > 0 : 

M , dj [= 8 and VO < k < j : M, <Jk 1= -•V’ioi(a) A -><5 and 

(30 < k < j : M, cr fc f= £ a p A AG-WfoZ(a) or 

(VO < k < j : M, crjfc 1= ~^E a p and M, <7j 1= AG 1 VioZ(a))) 

We can express this semantic definition in terms of a CTL formula as well: 

O a {p < A) —def A( 

(-.Viol(a) A -*6)U e 6/\ 

(-.«/* (-tf A E a p A AG-WioZ(a))V 
((H? a p A - 6)U e {5 A AG Viol{a)))))) 

The lines of the formula correspond to the lines of the truth condition. The 
second line expresses that 5 becomes true at a specific point in the future, that 
we consider the first time this happens, and that there cannot be a violation 
of the obligation until then. The third line expresses one side of the exclusive 
disjunction, saying that E a p occurs before the first and that there cannot be a 
violation afterwards. The fourth line expresses the other side of the disjunction, 
saying that E a p has not occurred before the first <5, and that starting from the 
point where <$, violations persist forever. The latter condition expresses that the 
information that the obligation is violated, is preserved. 

In the’ above definition, the obligation is always discharged by the occurrence 
of a deadline condition. So, for this variant, the obligation does not persist until 
after the deadline. Furthermore, the definition obeys the properties 1, 5 and 7 
of section 3. 

6 Practical aspects of deadlines 

In this section we briefly discuss a few aspects that start playing a role when 
looking at more concrete aspects of deadlines. 

The first aspect is the violation constant. In this paper the Viol constant 
has only one parameter, the agent a. However, we would actually like to tie the 
violation to a specific obligation incurred at a specific moment in time. This 
is necessary to distinguish two obligations for the same agent that might only 
differ in the timing. E.g. the obligation to pay the rent before the end of the 
month occurs every month. But each month it is a different obligation. This 
can be achieved through the addition of a unique identifier for each obligation. 
This definition provides a very operational means to deal with violations, as it 
gives explicit information about what has caused the violation and can therefore 
enable to reason about what are the consequences and sanctions related to the 
violation. 

However, at the same time this unique identifier would eliminate any logical 
relations between obligations that are connected, E.g. someone might have an 



obligation to pay a conference fee while (due to budget restrictions that became 
clear only later) it is from now on prohibited to pay for any conference. The 
two norms relate to the same person and have opposite effects on the action 
of paying. However, if each would be modelled with a violation constant with 
a different identifier they could not be related and the intuitive contradiction 
between the two would not exist. 

As a solution to this problem we could introduce violations that have the 
same parameters as the obligations to which they are linked. In this way it 
becomes possible to specify logical relations between violations of which the 
actor, the deadlines and the situation to be achieved are related. However, this 
has as consequence that the violations are now also modal operators! 

A second point that comes up right away is which logical relations should hold 
between the violations? Do we have 

(V a (p<6)A{p'-+ P ))—*V a (p'<6) 

and/or 

{V a (p<6)A(6'^6))—>V a (p<6') 

Of course these properties are directly coupled to the properties that we would 
like to have for the obligation operator. A complete investigation into this issue 
warrants a separate paper and therefore will not be pursued here. However we 
would like to point to [11] for some related work in this area. 

Closely related to the above item is the point that we made violations (and 
non-violations) persistent over time. Once a deadline is violated, this violation 
will never disappear again. This seems a bit contradictory to common practice 
where sanctions are defined as obligations, conditional on the occurrence of a 
violation, in order to make it possible for violations to be redeemed. So, we make 
a difference between a violation that has not been ’’made up for” yet and one for 
which a sanction has been exercised already. This aspect could be modelled by 
not having the violation persistent, but have an axiom that triggers a sanction 
(obligation) whenever a violation occurs. 

A second item that is important in practice is that obligations are often 
conditional and/or repeated. The above example on paying the rent is a very 
typical case of a repeated obligation. The whole obligation to pay rent, however, 
can be made conditional on the fact that the house is properly maintained by the 
owner. Related to this aspect is that more temporal conditions can be specified 
for the achievement. E.g. the salary should be paid between the 25th and the 
end of each month. 

Although we represent the deadline condition as a proposition in this paper, 
often it contains a relative temporal expression such as ’’the book should be paid 
within one week after delivery”. In order to express this type of conditions one 
should have a more powerful language in which explicit reference to time can be 
made. 

A last item to mention here is the use of discrete time in our model. This is 
particularly important to decide on the exact moment when a violation arises. 
In a model with continuous time the achievement of a fact (an action) has to 



have a duration (whereas the achievement in our model is always in one time 
step). So the definition of E a p has to be changed. On the other hand we can in 
this model with continuous time determine a violation before the deadline if it is 
impossible to achieve the required state before the deadline condition anymore. 

7 Conclusions 

In this paper we have shown that the use of a violation constant is in principle 
enough powerful to account for the deontic aspect of the deadlines. Of course a 
temporal logic is needed to account for the temporal aspects. Finally we used 
the stit operator E a to relate the achievement of a state to an agent. This is 
important, because we consider the deadlines to be directed towards an agent 
and thus this agent has the responsibility to fulfill it. We do not use dynamic 
logic to model explicit actions in order to keep the model as abstract as possible. 
However, an obvious connection between the operator presented and dynamic 
logic can be made through the use of Segerberg’s bringing it about operator [12]. 

We have also shown that a correct definition of deadlines in the formalism 
requires a modelling of the intuitive causal relation between the occurrence of the 
action before the deadline and the violation state. This causal relation makes the 
formal definition of a deadline quite complicated, although the simple intuitive 
picture of the semantics (given in section 2) is still valid. 
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